Advanced Clientless VPN access with NetScaler Gateway
-
Relative URLs cannot be identified at times.
-
Relative URLs generated dynamically cannot be identified.
Prerequisites
-
Wildcard server certificate - The advanced clientless VPN rewrites URLs in a unique manner. This uniqueness is maintained for every URL per user. For example, if the web-application is hosted on
https://webapp.customer.com, and the VPN virtual server is hosted onhttps://vpn.customer.com, then the advanced clientless VPN rewrites it ashttps://cvpneqwerty.vpn.customer.com. This means, every URL is rewritten as a subdomain of the VPN virtual server. In this new URL,cvpneqwertycan be decrypted back tohttps://webapp.customer.com. The stringcvpneqwertyis dynamic and therefore for SSL, you must bind the VPN virtual server with a wildcard certificate.If the server is hosted withhttps://vpn.customer.com, then the server certificate must now have entries for (vpn.customer.com and .vpn.customer.com) as part of certificates CN or SAN (where CN=common name, SAN= Subject Alternative Name). The process of binding this certificate remains the same on NetScaler Gateway. Note: Wildcard certificates only support one-level (that is ..customer.com is not allowed). If you are already using a Wildcard certificate (for *.customer.com) and hostinghttps://vpn.customer.com, this does not work for the advanced clientless VPN. You must get a new certificate with*.vpn.customer.com. -
WildCard DNS entry - The clients (web browsers) must resolve the advanced clientless VPN app’s FQDN. While setting up the NetScaler Gateway server, you must have configured a DNS entry to resolve vpn.customer.com. This allows the browser to resolve vpn.customer.com to your VPN virtual server's IP address. To resolve URLs like
https://cvpnqwerty.vpn.customer.comto the same IP (VPN virtual server's IP address, you must add a new record for the domain ofvpn.customer.com. Find the domain setting in your DNS server and add a new host record for "*" with the same IP address as before. After adding the host record, you must see successful ping responses forhttps://cpvnanything.vpn.customer.com.
Configure Advanced Clientless VPN access
set vpn parameter -clientlessVpnMode ON
set vpn parameter -advancedClientlessVpnMode ENABLED
set vpn sessionaction SessionActionName -advancedclientlessvpn ENABLED
-
In the NetScaler® GUI, navigate to Configuration> NetScaler> Global Settings.
-
On the Global Settings page, click Change Global Settings, and then select the Client Experience tab.
-
On the Client Experience tab, from the Clientless Access list, click On.
-
On the Client Experience tab, from the Advanced Clientless VPN Mode list, click Enabled. If you select STRICT from the Advanced Clientless VPN Mode list, the NetScaler appliance responds only to StoreFront URLs in classic clientless VPN form and blocks all other classic clientless VPN requests. This option provides a more secure configuration on the appliance for delivering internal web-resources.
-
If a session action is bound to the virtual server, you must enable the Advanced Clientless VPN Mode option for that session action as well from the Client Experience tab in the Configure NetScaler Gateway Session Profile page.
-
You can select the Override Global option to override the global settings.
-
You can configure the advanced clientless VPN feature at a session level as well.